Impacket Net

Enumerate AD users, groups, and shares via Net commands over SMB

Tool
impacket-net
Category
Post-Exploitation / AD Object Manipulation
Platform
linux
Requires
password
Protocols
SMB, RPC

Open in Command Manager

Syntax

Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.

impacket-net '<domain>/<user>:<password>'@'<ip>' user

Credential variants

The same attack using a different authentication material.

NTLM Hash requires NTLM hash

impacket-net -hashes ':<hash>' '<domain>/<user>'@'<ip>' user

List Groups requires password

impacket-net '<domain>/<user>:<password>'@'<ip>' group

List Shares requires password

impacket-net '<domain>/<user>:<password>'@'<ip>' share

Examples

impacket-net 'CORP.LOCAL/user:password'@192.168.1.100 user

Tags

impacket net users enumeration smb